Executive brief
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Zimbra Classic Web Client. The flaw allows remote attackers to impact the confidentiality and integrity of data via improper neutralization of input during web page generation.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8 before 8.8.15 Patch 41
Timeline
- 2023-07-27: disclosed: Date added to CISA KEV catalog
- 2023-07-27: kev added
- 2023-07-27: advisory
- 2023-07-27: exploited: Reported as exploited in the wild per CISA KEV inclusion.